← Vulnerability feed

Vulnerability record · CVE-2020-15922 · published 24 July 2020

CVE-2020-15922: Mida eFramework OS command injection enables root RCE

Midasolutions · Eframework

Mida eFramework 2.9.0 contains an OS command injection flaw (CWE-78) that lets an attacker run arbitrary commands and achieve remote code execution with administrative (root) privileges. The description states authentication is required, yet the CVSS 3.1 vector is PR:N, so the record is internally inconsistent on whether credentials are needed. Because successful exploitation yields root-level code execution, the flaw is severe for any exposed deployment.

9.8 CVSS 3.1 Critical EPSS 57% · top 1.0% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityRemote code execution as root with a critical CVSS score, public exploit references and very high EPSS make this an urgent fix despite the authentication ambiguity.

What it is

Mida eFramework 2.9.0 contains an OS command injection flaw (CWE-78) that lets an attacker run arbitrary commands and achieve remote code execution with administrative (root) privileges. The description states authentication is required, yet the CVSS 3.1 vector is PR:N, so the record is internally inconsistent on whether credentials are needed. Because successful exploitation yields root-level code execution, the flaw is severe for any exposed deployment.

Impact

An attacker who can reach the vulnerable functionality gains arbitrary command execution as root, effectively full control of the host. That permits data theft, service disruption, persistence and lateral movement from the compromised server.

Attack surface

The flaw is network-reachable (AV:N) with low attack complexity and no user interaction (UI:N). The description says authentication is required, but the CVSS vector claims no privileges are needed (PR:N); the record does not resolve this contradiction, so treat both authenticated and unauthenticated reachability as possible until verified.

Exploitation

CVE-2020-15922 is not listed in CISA KEV, but public exploit references exist (Packet Storm and a third-party advisory both tagged Exploit), and EPSS is high at roughly 0.57 probability (99th percentile), indicating elevated likelihood of exploitation. No ransomware group is documented as using it.

What to do

  • Apply the vendor fix for Mida eFramework or upgrade past the affected 2.9.0 release; if no patch is available, isolate or retire the product.
  • Restrict network access to the eFramework interface with firewall rules or a VPN so only trusted administrators can reach it.
  • Enforce strong authentication and least privilege on the application, and do not expose its management interface to the internet.
  • Monitor and constrain the web server process so it cannot spawn shell commands, for example via application allowlisting or container isolation.
  • Review logs and host activity for signs of compromise if the system was internet-facing before remediation.

Detection

  • Alert on child processes spawned by the eFramework web server (for example sh, bash, cmd, curl, wget) using process creation telemetry.
  • Inspect web and application logs for command metacharacters (;, |, &&, backticks, $()) in request parameters tied to the vulnerable endpoint.
  • Monitor for outbound connections or file writes originating from the eFramework service account that are unusual for normal operation.
  • Correlate authentication events with subsequent command execution to catch both authenticated abuse and any unauthenticated path.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-15922 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-15921Midasolutions eframework improper authentication vulnerabilityMida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as …EPSS 18%9.8CVE-2020-15920Mida eFramework OS command injection allows unauthenticated root RCEMida eFramework through 2.9.0 contains an OS command injection flaw (CWE-78) that lets an unauthenticated attacker execute arbitrary commands on the …EPSS 98%analysed7.5CVE-2020-15923Midasolutions eframework path traversal vulnerabilityMida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.EPSS 3.3%7.5CVE-2020-15924Midasolutions eframework sql injection vulnerabilityThere is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point re…EPSS 1.9%6.1CVE-2020-15919Midasolutions eframework cross-site scripting vulnerabilityA Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.EPSS 0.94%5.4CVE-2020-15918Midasolutions eframework cross-site scripting vulnerabilityMultiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.EPSS 0.56%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed

Source: NIST National Vulnerability Database (record CVE-2020-15922), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.